Static | ZeroBOX

PE Compile Time

2024-08-11 05:09:06

PDB Path

c:\wmaogm116irqog\obj\Release\MSG.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000663f4 0x00066400 7.99780737325
.rsrc 0x0006a000 0x000005e0 0x00000600 4.17016319154
.reloc 0x0006c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0006a0a0 0x0000034c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0006a3f0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
'rPM(_
xhZb9
HkS6F
5cG:Cttsplr
jX`i!@
<eL/|
^c.hvl`R
CRgRVp
V~{rx,
U]dE;,
2[`]b|
q )@%n
6cKu*&w
RRA".g
-@O2WJ(nG:&4
Cn^t'o
I7+CNV
6C;U0v
G/1(A>
{40s!X?
UY,Yh6K
Uf{kjE
MXMo}'
_GcvZ)
R7T>sz
K~I_xI$
%5,~q+
Z75">"
}AC#K>
t'h'bj9
PGTri\J
}UB8n;
*%IpzP
@{q"P[
P.f[up
=@Vk<N
{6N0JK
q>JS]o,f
Du_%1_u
cmZ<w7G
IS: zV
WlWx}%B{
boCvkv
ykG5Jo
[pELD+V
QD82Kr>
1.=ZC
rx_/4G
?@]Mm#D
`p"'Fc
9"L#<$
Sz,R;pX&
="PyBhY
Q[7C*3
W)GKWE1
}_y."%
j.fYB[A
w`Y#^b4
az.`X!C
A8x/ob
^HgnSMq
CMr=>$
Zz&mr#g
H{Jv"*M
(!S,MJ
dT+]Wd
2a\kfE
v<;@,p
o(=T6D/
MkjWK%s
yI8IL;
&_p<i.
*7XHq>
KUA#x'
EEu}9:
4s`@L-
vYeC!E
Q9Yi$E
MQP0I
f~rc([
KNoT'`L
oacyH<g
mLM%aE
^%$sf)
xid!~U-
Yx82C.B
c9#=/MKQ
:%{}Cu
hYqD6M]
GaF4l(Z
@BP&wk
9/$yAvj
BY;ll[=
|6}~!K3
LFodc8
?Ywi@|
3c40<m
u;>ac&
[-vKpRn>
jz17enS
ZeF~Au.
]6:&\2@h
ea Wvdc
60n.Hw
u;Urk"(>SU
(o1L Gx
TE@?8]R
B,N8~v!
`13f3>
K#gMOo
"cIMnc
3D)c.nV
D^I>kM
X$cwG'
)-J]j6
.aZd(u
mp+J}O
poa-+,
M5[Zk<
Lj^:c5
uz9_TF!E]
R>-2^#
,7cqmV
C!Ro=|
n357}|c}
xp}:vi~
;*f.jr
U}5O>J
&byWxB
-e-~'e
&nJ8B1l
p!xCdq
QT~#9=
mZa8sY
|*4>P.
P;vC*[W
"uv|)k
i.(?w
)JO'Y|
D6VRm`y|
AF<{IX
KdSFP)
wjqIIMRsu
@CS<6m
sQcyIgS
nROv[j7
-=a3ut
Br@=-6
^^UW~v
4o?Jk06
o+k#Z
@WJb1W^
Ek~]#D
4`(B-Q
D%^Uss
!D3FB`
Z%M<yMZ*
ml$0M`
kz[ZtO
}8L1Y}
,zK0gz'
fYuHdkm
glb/6tI
B]W)f{md
V T~yDs
[fyKUi
(8kUW0O
"YAp/A
sm\NBi
c]CvM_m-
a;M!1)
o;)$if
Y/C'v}(
;9>8|}}/f
(gWc!<T
*,i/Y%
;t88;p
UK*'o|Y
+^GtFd^
y#4DEU
w+OFG}
/( lSQ
ke/;-amM$
D(d*Z/;Dk8
k ]*S\
e#Lh%lC
mF;*H
rl:!2"
*Y,oe{
)L\N$r:
uP{\2\
P^}14[3Td
Cf[u_qh@
f|vK9(
l+_1Ys0
WC5g;U
r;by+A
g(jvUv
ND:dL
OKxfpl
okmT`&9
r)Um3R
&eT;n8
6<c}C8$
<)9qY
PN!O,Mr6
5B[77%1zU
;>9qr/
84vx`L
Nqs|Cw
j1{'G{
yl4ZAv
O3f7XJ
!smp_-u
\myy(t
6#{D \
:P/;1q
!90wA\
IHjhy~O
w1+(es
%[``_j5
<_fOX
XDBe`W
T:r0O3
YA;`muB
}5qShX
+lkT!|r
+IIDKG
*>duA=g
6w\pnp
zifiSJ
R+G}Y96
/0a}BX>P1
2^7-~:
$Jb)aM
?,C.)?vM
h]hWDz
kvi}|B
cFTJ:_0
f5VM~R'
,956KT^
3Z$zS
*X2}BC
n.|pGY
)]ovQW
[\*<d /
=3*rB_
UbnOh
]TO!Yt
:R(pzB
{WpZS}YH
$SPmuG
ZZ<{'4
pUf?B<
"m?A-,
[Syc^q
H;v$jB
64*sC6
smB5r:
~IF?&C/
ibuSA
Zu*y5U
qLIm!GJ
fydGSNb
m1mo>bS
fsP/mP
AB1mH6
!(F!&P
be^+d
0Y#J"-
)^@' %
._bZg^
&}!E Z
<NG4i3
q`}5'#
,nXD>Z
0+eCet
I;zYVx
eQk<af
T+CrK}
'DRo(s
QiX0 ,
[4),*+
Q~n^\U
K2qm)a
AP3 (xc/g
ED"uQ
VfBw[_
yh!}G{f)
*hYSBx
Ve6*@ANW
ziY=x.
iLFWd'
OjT0eDtDwR
L{Xc>I
,&IK!]1
O8Mk:B
-iM9$B
O[jBRN
wC}Dd3
82Z~{^
+ad"S
m>]qrC/
v2SCGA:
<c(w;:RE!
:AN+e
^O1q:YYn
N0s#FE
Fv)QVk|
-x8e)-
bmbV@w
"xus3
EJSb!s]\
n-,)$8
c}p<:3:7q
M7Zf:"P
'o4;\QV
+C!NY,*
sWF}J-3
-2^.>uZ
tsGA-9
u_*Ey/
rF-aO)6
/.D'B$
[,!M^h
\}|Jv$
9q@fE{ Y
,zJnmc
E2Bs(:
]+'(rn
0$w: I]
ZY !m?
yKV$ U
2e][oWI
Zm2TwYq@
uQV#qH
3.+u*7z!
cS@SNx
;z5=:q
J-3AG[
[PK#,1\R
"BCQNq
O=V{AY
3qB<&g)
DF")`SFx
IdY~YI0{
4Sn\#h;
edy-9Cp
.$W}S)6
J^HEi]=
<82Epn
9@NG~2
0H)}KP7
O#KMk!
0`B)H-Do
|<p&Ok%`
#k6j3wC
tQzEf9S+f
?>'PUv
{w(^CI
j40XM4[
q.Z$Uq7
4DL#!PU
@@L;+_3
fodF ^gC
y~=`]2
)n=k]^P6
l^1$28Iz
tR\#(G
+!,EBu
U`>^(>
BrO7F
jWD\Gz*,U
H$=SzQk
FGVa8V@
d4j'})
?%5eXb
d6l!14
~@8CwdWm
`BS9H/
=}\CJ
K)webU
NLGZBG
H+aL}F>\
[KSyb^
|2_;k+
U~n"6
g'!P;%
0/r:Ge
"@WD"F
kGo?lt
`m([{l;>L
u;M]#F
|`q<+,D
'>f>NP
0T`<'b
E+\F<<
]qQ:dTw
Atlh-wO
})jj?=
YJ>Jl7,
I[>r1|Q
^{j0;s
?;An>
.,{E(0)
6m-PJ'^8
'z?oe
%jd8i!
&cmfb
5G'd}j
q>q+[k
}zw/9)
n]\XA=
;)BpS?
jeTK"u
Og 6CQa
M6mcRl
R675u)
GCCC*6
;bh%+
M`O:fR
k.sz":
4w|,O%
te*ymF
im?H4r
?v"N`6
Vyt6p
(qY{SN
Cfth/l
)LXT+54
n%C|(B
V+&<C_
y~oK&n
Tn@!)~
"d=<R/[
<AlloqkS
>Y+o^gd
/0}Py-
}D^+Be)
M:q^=uH
}^/A[j
!kp[i4yT
K~VA,w
0}%&4?m
w(^RnC
\R?hh0
mp1>2s
L=\z N
h*\%>k
KIsba,
[mrB90
&Ck-2q
5ID;Z
,E{^/v
aXL.IGB
y`BR}5
hDe{9J
L-_$sGE
Z,ct !
bwVA8OJ"
{_rBbw2
;Fcv@t
*mN4Erp
a&tc2g
1,5/*2,
jjdb*]27m`n
`2(n5v
KF!U1j
bx;jQR
efRfko
Z!y\e}
D#?Bc+
s``ci{
j.sU=
;/<S<-
})QJo2w
Oq?/[/
ten.Q2
eWtGuny@v
Ja0(%=
Eo\*DH
bE=(9s
OTo9xZ
zx{b=c
TFZRjA#)^S
dqyCb:
+|z1KW
%ScU"H
w*f~aa
>{-0i
/~^`cF
_1_:Tdm:Ho
b3Z/Hi
6s%rSk
1*gXh
b,K_3H
we4P$m{
Xfp(Zv
:ZG&LvU
e'1,J8
yUfJtw<
s`j>L=
5v-V4w
-Ag_Y[
z#>/B;
@X8V/t
gy55ip
31(pvW
x1V!+kfF}
(!2qnu
DgG21";
<[}N,1>
Jx7|j.%_
KD+e'{[
%VT:[]
m&cK'q0,
?(NtL|
uI;Ba`q
JOGaKR
.$V *7
QTbR#5
l<|*6j
6^1YH`
Xdyb8D
<H=6~S
{}e=D>P
c[{z:L
;R{=(}
"B8>'[
$ogA:f~v$q
/ ZpHx5
CB`R#M
J E\@l
.1Aa.=J
Mc23zl#
AR>Od\
B(y4d@
Ak/k&)hO
2Ltr]H
^zTwoL
>r]&_s
|z>RPD
q7I8v2
-'n?mR
V,HVid
a6ts"(
[&<]XjO
z`_k~j1
BeK<[S
=@r#93
6oX-7:
$~d*-<
<F%^UMyq
[akLdrB
}k_lF'
ty90/I
S-ev~[
#8F]Q#,
V.!<2P
4`p^f+
ZEwHuE
6"#Cg\
$5)fm
C3OF\-
B_Ms4TN5
3R*`SKl
aU,wc7G
cOvyT.
rP+!EG
$7dN[u^
.&pP'
PAT:9>=/
mA$2W9
_Ovh(P8E
~<#Jk6[
=nS<gS
p.W>.R
6w&b+e5s
k7PH/-
a%-4z}^
[G8Ro}fs
7_`lzv
wu)~;D+t
D\#TuW
^W)G|T)
$nMeHJ
irq:y3
4B3Qe?`
s<u}7s6e
Um\U/C
"fPs^a
R^0xe+
8{x,>Dqd B
:1fBdB
0%pAka
J<='r,;
7w,0}i
+_,LvO
dG\H$B
NZ<**6
9=vAVke
>=k_T%=
6gWZY>
teH9YZ
ug&N6b\
[e)j8K_U
WK*Y_'
n>]=LE
}FZ{3U
(Et&M
m+ks4wt
W=_aI=
HO]kC]
_zx65(
@jkh1n
$}Mg_wy
#/pY}M]
N;~x>]
W#82=027
U4%\|iX$
&&b3e
Wy)Lvt
pO,Vsv
xyf55S
)P;s,l
'Ov?b?
]*@oGOG\
Wr<]i>6
t]5FQk
>6Oyld
-E9J$9
hXFe:bF
SSn8RW
KbUt)V
~-|p&.
#)}>{K
vx?B{DPo
Yo-,ks
F Bjx@{
4ZqRgy
cthnB.N
F9%Z-&f
;3Usv+
[+(v0O}*
{h)mLz
db`^.6
b62[#]
a3juRq|
`4BT*]n#
k"-(x++
ynLxX3#
W~c?Wb
NAhIKe}&
+]x=Ps
e|*)KB
cp1T@VD`
#x~`%r\
c -0-
2Eoi%>D
+fz[NE
hGz:mi
R3^GVf
I%AZ4@
U/C}W$
T\|[=S)
5p3@Q{
>hdw
Ic Iu@
[#ts#%
HT0F[jX
x_v>m+
,[Ihod
g*P`4n
npNt.:g
i0=.]*:
?%`` <
TN(iX{3uL
SgS"o'
xrJ2=J]A
jk-pj8,
k$0M4 x
*lPs?%
76e|;-
/*w <Ee
M# [P!n8_
f$wU-J
=TKbBx
"E\bz^.
r<z2?q
QG4I0H
.nHAv~
:qUIT`
%H_*Ve
L\|l=3PZ
&d sNl
$IL6({
GqFqel
Ux5m`lyR
\jCr4PzJX
w@R}oa
$0-GG
A1Ql^89
k-uOvMk
s`6a~~
f[9CCV["m
\6QFe|W
wgF;0Y
gUSDcA
GVb<+ R
BGEXO!
sEs*[3
Lp#[tNp
6Bq$7g
QX/4!>
;1],uv~
~+T?G
4ad8NM
]lzUt7t
|GU*"#
epTr.$
?,5U_ki7Z
_Q%VSl
v4.0.30319
#Strings
<Module>
MSG.exe
MoveAngles
SplitSettings
Program
mscorlib
System
Object
userBuffer
Status
DoSplit
WaitForSingleObjectEx
VirtualProtect
CreateRemoteThread
EnableHTTP
shellKey
splitType
uzBAyuisuyi
ZAdhhytjuy
listenning
AZsadffde
Valeoz
System.Runtime.Versioning
TargetFrameworkAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyCultureAttribute
System.Runtime.InteropServices
ComVisibleAttribute
GuidAttribute
AssemblyVersionAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
.cctor
rivateImplementationDetails>{81AC3D71-5B93-4C4F-94C8-1189F17DA357}
CompilerGeneratedAttribute
ValueType
__StaticArrayInitTypeSize=16
$$method0x600000b-1
RuntimeHelpers
RuntimeFieldHandle
InitializeArray
__StaticArrayInitTypeSize=412672
$$method0x600000b-2
String
Concat
Console
WriteLine
Convert
ToBoolean
get_Chars
get_Length
DllImportAttribute
kernel32.dll
ToByte
System.Collections.Generic
List`1
Exception
get_Message
OperationCanceledException
Random
$$method0x600000c-1
__StaticArrayInitTypeSize=1196
$$method0x600000c-2
.NETFramework,Version=v4.7.1
FrameworkDisplayName
.NET Framework 4.7.1
Interruptible marbleised
Photoreceptor
Volatilization Swellings
Good resorters
Copyright
2024
$375c5eff-0650-4301-85ef-382cfefa9adf
1.0.0.0
WrapNonExceptionThrows
c:\wmaogm116irqog\obj\Release\MSG.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Splitter:
Exception:
Custom definitions
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Photoreceptor
CompanyName
Volatilization Swellings
FileDescription
Interruptible marbleised
FileVersion
1.0.0.0
InternalName
MSG.exe
LegalCopyright
Copyright
2024
OriginalFilename
MSG.exe
ProductName
Good resorters
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
huorong Trojan/MSIL.Agent.li
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AMCP
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Stealerc.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!4BEAD3A1A968
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.4bead3a1a9683a32
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealerc.gen
Microsoft Program:Win32/Wacapew.C!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.86 (RDM.MSIL2:TJOAkZ5IuiFliHAd52ZSJg)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.AMBW!tr
BitDefenderTheta Gen:NN.ZemsilF.36810.zm0@a8JmbNl
AVG Win32:PWSX-gen [Trj]
DeepInstinct Clean
CrowdStrike win/malicious_confidence_90% (D)
alibabacloud Clean
No IRMA results available.